var express = require('express');
var router = express.Router();
var db = require("../db.js");

/* GET users listing. */
router.get('/', function(req, res, next) {
  res.send('respond with a resource');
});
router.post('/login', function(req, res, next) { //登录
    let username = req.body.username;
    let userpassword = req.body.password;
    db.query("select * from users where U_LoginID='" + username + "'", function(err, rows) {
        if (err) {
            console.log(err.message);
            return;
        } else {
            if (rows.length > 0) {
                if (userpassword == rows[0].U_PassWord) {
                    let obj= rows[0]
                    delete obj.U_PassWord
                    res.send({
                        status: 1,
                        msg: "登录成功",
                        data: rows[0]
                    });
                } else {
                    res.send({
                        status: 0,
                        msg: "账号或密码错误，请重新填写。",
                        data: null,
                    });
                }
            } else {
                res.send({
                    status: 0,
                    msg: "账号或密码错误，请重新填写。",
                    data: null,
                });
            }
        }
    })
});

router.get('/searchfriend', function(req, res, next) { //搜索好友
    let kwd = req.query.kwd;
    let UId = req.query.UId;

    db.query("select U_Uid,U_NickName,U_SignaTure,U_Sex,U_HeadPortrait,U_Age,F_Name from users u left join friends f on u.U_Uid = f.F_FirendID   where (U_NickName like'%" + kwd + "%' or F_Name like '%" + kwd + "%') and f.F_UserID = '" + UId + "'", function(err, rows) {
        if (err) {
            console.log(err.message);
            return;
        } else {
            res.send({
                status: 1,
                msg: "搜索成功",
                data:rows,
            });
        }
    })

});

module.exports = router;
